Debian Xen vulnerabilities
444 known vulnerabilities affecting debian/xen.
Total CVEs
444
CISA KEV
0
Public exploits
9
Exploited in wild
1
Severity breakdown
CRITICAL18HIGH137MEDIUM226LOW63
Vulnerabilities
Page 18 of 23
CVE-2013-1964P4MEDIUMCVSS 6.9fixed in xen 4.1.4-3 (bookworm)2013
CVE-2013-1964 [MEDIUM] CVE-2013-1964: xen - Xen 4.0.x and 4.1.x incorrectly releases a grant reference when releasing a non-...
Xen 4.0.x and 4.1.x incorrectly releases a grant reference when releasing a non-v1, non-transitive grant, which allows local guest administrators to cause a denial of service (host crash), obtain sensitive information, or possibly have other impacts via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.1.4-3)
bullseye: resolved (fixed in 4.1.4-3)
forky: r
debian
CVE-2017-15596P4MEDIUMCVSS 6.0fixed in xen 4.8.1-1+deb9u3 (bookworm)2017
CVE-2017-15596 [MEDIUM] CVE-2017-15596: xen - An issue was discovered in Xen 4.4.x through 4.9.x allowing ARM guest OS users t...
An issue was discovered in Xen 4.4.x through 4.9.x allowing ARM guest OS users to cause a denial of service (prevent physical CPU usage) because of lock mishandling upon detection of an add-to-physmap error.
Scope: local
bookworm: resolved (fixed in 4.8.1-1+deb9u3)
bullseye: resolved (fixed in 4.8.1-1+deb9u3)
forky: resolved (fixed in 4.8.1-1+deb9u3)
sid: resolved (fi
debian
CVE-2014-1895P4MEDIUMCVSS 5.8fixed in xen 4.4.0-1 (bookworm)2014
CVE-2014-1895 [MEDIUM] CVE-2014-1895: xen - Off-by-one error in the flask_security_avc_cachestats function in xsm/flask/flas...
Off-by-one error in the flask_security_avc_cachestats function in xsm/flask/flask_op.c in Xen 4.2.x and 4.3.x, when the maximum number of physical CPUs are in use, allows local users to cause a denial of service (host crash) or obtain sensitive information from hypervisor memory by leveraging a FLASK_AVC_CACHESTAT hypercall, which triggers a buffer over-read.
Scope: loc
debian
CVE-2013-4356P4MEDIUMCVSS 5.4fixed in xen 4.4.0-1 (bookworm)2013
CVE-2013-4356 [MEDIUM] CVE-2013-4356: xen - Xen 4.3.x writes hypervisor mappings to certain shadow pagetables when live migr...
Xen 4.3.x writes hypervisor mappings to certain shadow pagetables when live migration is performed on hosts with more than 5TB of RAM, which allows local 64-bit PV guests to read or write to invalid memory and cause a denial of service (crash).
Scope: local
bookworm: resolved (fixed in 4.4.0-1)
bullseye: resolved (fixed in 4.4.0-1)
forky: resolved (fixed in 4.4.0-1)
sid
debian
CVE-2019-17349P4MEDIUMCVSS 5.5fixed in xen 4.11.3+24-g14b62ab3e5-1 (bookworm)2019
CVE-2019-17349 [MEDIUM] CVE-2019-17349: xen - An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cau...
An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cause a denial of service (infinite loop) involving a LoadExcl or StoreExcl operation.
Scope: local
bookworm: resolved (fixed in 4.11.3+24-g14b62ab3e5-1)
bullseye: resolved (fixed in 4.11.3+24-g14b62ab3e5-1)
forky: resolved (fixed in 4.11.3+24-g14b62ab3e5-1)
sid: resolved (fixed in 4.11.3+24-
debian
CVE-2019-17350P4MEDIUMCVSS 5.5fixed in xen 4.11.3+24-g14b62ab3e5-1 (bookworm)2019
CVE-2019-17350 [MEDIUM] CVE-2019-17350: xen - An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cau...
An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cause a denial of service (infinite loop) involving a compare-and-exchange operation.
Scope: local
bookworm: resolved (fixed in 4.11.3+24-g14b62ab3e5-1)
bullseye: resolved (fixed in 4.11.3+24-g14b62ab3e5-1)
forky: resolved (fixed in 4.11.3+24-g14b62ab3e5-1)
sid: resolved (fixed in 4.11.3+24-g
debian
CVE-2013-4494P4MEDIUMCVSS 5.2fixed in xen 4.4.0-1 (bookworm)2013
CVE-2013-4494 [MEDIUM] CVE-2013-4494: xen - Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_t...
Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators with access to multiple vcpus to cause a denial of service (host deadlock) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.4.0-1)
bullseye: resolved (fixed in 4.4.0-1)
forky: resolved (fixed in 4.4.0-1)
debian
CVE-2015-5307P4MEDIUMCVSS 4.9fixed in linux 4.2.6-1 (bookworm)2015
CVE-2015-5307 [MEDIUM] CVE-2015-5307: linux - The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x...
The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #AC (aka Alignment Check) exceptions, related to svm.c and vmx.c.
Scope: local
bookworm: resolved (fixed in 4.2.6-1)
bullseye: resolved (fixed in 4.2.6-1)
forky: resolved (fixed in 4.2.6-1)
sid:
debian
CVE-2015-2752P4MEDIUMCVSS 4.9fixed in xen 4.4.1-9 (bookworm)2015
CVE-2015-2752 [MEDIUM] CVE-2015-2752: xen - The XEN_DOMCTL_memory_mapping hypercall in Xen 3.2.x through 4.5.x, when using a...
The XEN_DOMCTL_memory_mapping hypercall in Xen 3.2.x through 4.5.x, when using a PCI passthrough device, is not preemptible, which allows local x86 HVM domain users to cause a denial of service (host CPU consumption) via a crafted request to the device model (qemu-dm).
Scope: local
bookworm: resolved (fixed in 4.4.1-9)
bullseye: resolved (fixed in 4.4.1-9)
forky: resolv
debian
CVE-2012-6032P4LOWCVSS 6.9fixed in xen 4.1.4-1 (bookworm)2012
CVE-2012-6032 [MEDIUM] CVE-2012-6032: xen - Multiple integer overflows in the (1) tmh_copy_from_client and (2) tmh_copy_to_c...
Multiple integer overflows in the (1) tmh_copy_from_client and (2) tmh_copy_to_client functions in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4.2 allow local guest OS users to cause a denial of service (memory corruption and host crash) via unspecified vectors. NOTE: this issue was originally published as part of CVE-2012-3497, which was too general; CVE-2012-3
debian
CVE-2016-2271P4MEDIUMCVSS 5.5fixed in xen 4.8.0~rc3-1 (bookworm)2016
CVE-2016-2271 [MEDIUM] CVE-2016-2271: xen - VMX in Xen 4.6.x and earlier, when using an Intel or Cyrix CPU, allows local HVM...
VMX in Xen 4.6.x and earlier, when using an Intel or Cyrix CPU, allows local HVM guest users to cause a denial of service (guest crash) via vectors related to a non-canonical RIP.
Scope: local
bookworm: resolved (fixed in 4.8.0~rc3-1)
bullseye: resolved (fixed in 4.8.0~rc3-1)
forky: resolved (fixed in 4.8.0~rc3-1)
sid: resolved (fixed in 4.8.0~rc3-1)
trixie: resolved (f
debian
CVE-2013-4553P4MEDIUMCVSS 5.2fixed in xen 4.4.0-1 (bookworm)2013
CVE-2013-4553 [MEDIUM] CVE-2013-4553: xen - The XEN_DOMCTL_getmemlist hypercall in Xen 3.4.x through 4.3.x (possibly 4.3.1) ...
The XEN_DOMCTL_getmemlist hypercall in Xen 3.4.x through 4.3.x (possibly 4.3.1) does not always obtain the page_alloc_lock and mm_rwlock in the same order, which allows local guest administrators to cause a denial of service (host deadlock).
Scope: local
bookworm: resolved (fixed in 4.4.0-1)
bullseye: resolved (fixed in 4.4.0-1)
forky: resolved (fixed in 4.4.0-1)
sid: r
debian
CVE-2013-2077P4MEDIUMCVSS 5.2fixed in xen 4.2.2-1 (bookworm)2013
CVE-2013-2077 [MEDIUM] CVE-2013-2077: xen - Xen 4.0.x, 4.1.x, and 4.2.x does not properly restrict the contents of a XRSTOR,...
Xen 4.0.x, 4.1.x, and 4.2.x does not properly restrict the contents of a XRSTOR, which allows local PV guest users to cause a denial of service (unhandled exception and hypervisor crash) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.2.2-1)
bullseye: resolved (fixed in 4.2.2-1)
forky: resolved (fixed in 4.2.2-1)
sid: resolved (fixed in 4.2.2-1)
tri
debian
CVE-2014-8867P4MEDIUMCVSS 4.9fixed in xen 4.4.1-5 (bookworm)2014
CVE-2014-8867 [MEDIUM] CVE-2014-8867: xen - The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, 3.2.x, and...
The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, 3.2.x, and earlier lacks properly bounds checking for memory mapped I/O (MMIO) emulated in the hypervisor, which allows local HVM guests to cause a denial of service (host crash) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.4.1-5)
bullseye: resolved (fixed in 4.4.1-5)
forky: re
debian
CVE-2015-4103P4MEDIUMCVSS 4.9fixed in qemu 1:2.3+dfsg-5 (bookworm)2015
CVE-2015-4103 [MEDIUM] CVE-2015-4103: qemu - Xen 3.3.x through 4.5.x does not properly restrict write access to the host MSI ...
Xen 3.3.x through 4.5.x does not properly restrict write access to the host MSI message data field, which allows local x86 HVM guest administrators to cause a denial of service (host interrupt handling confusion) via vectors related to qemu and accessing spanning multiple fields.
Scope: local
bookworm: resolved (fixed in 1:2.3+dfsg-5)
bullseye: resolved (fixed in 1:2.3
debian
CVE-2015-2756P4MEDIUMCVSS 4.9fixed in qemu 1:2.3+dfsg-3 (bookworm)2015
CVE-2015-2756 [MEDIUM] CVE-2015-2756: qemu - QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to P...
QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.
Sco
debian
CVE-2015-7970P4MEDIUMCVSS 4.9fixed in xen 4.6.0-1 (bookworm)2015
CVE-2015-7970 [MEDIUM] CVE-2015-7970: xen - The p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod.c in Xen 3.4.x, 3.5....
The p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod.c in Xen 3.4.x, 3.5.x, and 3.6.x is not preemptible, which allows local x86 HVM guest administrators to cause a denial of service (CPU consumption and possibly reboot) via crafted memory contents that triggers a "time-consuming linear scan," related to Populate-on-Demand.
Scope: local
bookworm: resolved (fixed
debian
CVE-2015-7969P4MEDIUMCVSS 4.9fixed in xen 4.6.0-1 (bookworm)2015
CVE-2015-7969 [MEDIUM] CVE-2015-7969: xen - Multiple memory leaks in Xen 4.0 through 4.6.x allow local guest administrators ...
Multiple memory leaks in Xen 4.0 through 4.6.x allow local guest administrators or domains with certain permission to cause a denial of service (memory consumption) via a large number of "teardowns" of domains with the vcpu pointer array allocated using the (1) XEN_DOMCTL_max_vcpus hypercall or the xenoprofile state vcpu pointer array allocated using the (2) XENOPROF_ge
debian
CVE-2015-8339P4MEDIUMCVSS 4.7fixed in xen 4.8.0~rc3-1 (bookworm)2015
CVE-2015-8339 [MEDIUM] CVE-2015-8339: xen - The memory_exchange function in common/memory.c in Xen 3.2.x through 4.6.x does ...
The memory_exchange function in common/memory.c in Xen 3.2.x through 4.6.x does not properly hand back pages to a domain, which might allow guest OS administrators to cause a denial of service (host crash) via unspecified vectors related to domain teardown.
Scope: local
bookworm: resolved (fixed in 4.8.0~rc3-1)
bullseye: resolved (fixed in 4.8.0~rc3-1)
forky: resolved (
debian
CVE-2013-1919P4MEDIUMCVSS 4.7fixed in xen 4.1.4-3 (bookworm)2013
CVE-2013-1919 [MEDIUM] CVE-2013-1919: xen - Xen 4.2.x and 4.1.x does not properly restrict access to IRQs, which allows loca...
Xen 4.2.x and 4.1.x does not properly restrict access to IRQs, which allows local stub domain clients to gain access to IRQs and cause a denial of service via vectors related to "passed-through IRQs or PCI devices."
Scope: local
bookworm: resolved (fixed in 4.1.4-3)
bullseye: resolved (fixed in 4.1.4-3)
forky: resolved (fixed in 4.1.4-3)
sid: resolved (fixed in 4.1.4-3)
debian